Critical Deserialization, SSRF, and Hard‑Coded Credential Flaws in Grid Protection Alliance openPDC/openHistorian
CISA reports six CVEs (CVSS 9.8) in openPDC and openHistorian that enable unauthenticated attackers to execute arbitrary code or perform SSRF. The flaws test the control objective of secure software lifecycle management, a key trust signal for energy‑sector auditors.
ADTP Breach Watch· October 8, 2026· CISA Advisories
SeverityCritical
Type☁️ Vulnerability
ConfidenceHigh
ReportedOct 8, 2026
Energy & UtilitiesEnergy utilities and grid operators using openPDC/openHistorianVulnerability Exploit
What happened
OpenPDC versions <2.9.482 and openHistorian versions <2.8.585 contain unsafe deserialization, missing authentication, SSRF, hard‑coded credentials, and unsafe reflection. An unauthenticated network attacker can exploit these to run arbitrary code on the host system.
Why it matters for trust and compliance
The incident highlights the need for continuous vulnerability monitoring and evidence of timely patching—core to the control objective of secure software development and a demonstrable audit trail under NIST CSF 2.0.
Shows the importance of continuous vulnerability scanning and patch‑management evidence for audit readiness.
Supports the control objective of secure software lifecycle, satisfying multiple frameworks through a single control.
Who is affected
Energy utilities and grid operators using openPDC/openHistorian
Recommended actions
Upgrade openPDC to ≥ 2.9.482 and openHistorian to ≥ 2.8.585.
Enforce Windows Authentication on all console interfaces.
Run a full vulnerability scan on grid‑control assets and remediate any findings.
Record patch‑deployment dates and configuration changes in your continuous monitoring platform.